PT-2006-2624 · Adobe+1 · Shockwave Flash+3

Hoshikuzu Star_Dust

+1

·

Publicado

2006-04-05

·

Atualizado

2021-07-23

·

CVE-2006-1626

CVSS v2.0

4.3

Média

VetorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions: Internet Explorer 6 for Windows XP SP2 and earlier
Description: A spoofing issue exists that could allow an attacker to display spoofed content in a browser window. The address bar and other parts of the trust UI can be displayed from trusted Web sites, but the content of the window contains the attacker's Web page. This can be achieved by re-opening the window to a malicious Shockwave Flash application, then changing the window location back to a trusted URL while the Flash application is still loading.
Recommendations: For Internet Explorer 6 for Windows XP SP2 and earlier, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2006-1626

Produtos afetados

Internet Explorer
Internet Explorer 6
Shockwave Flash
Windows Xp